Penetration testing, often shortened to pentesting, is a controlled attack against systems you own or have written permission to test. The aim is not to embarrass a development team. The aim is to find the holes a real attacker would find, and to write them down so they get closed.
In Australia you will also hear VAPT, vulnerability assessment and penetration testing. Treat that as a reminder that scanning and testing are both useful, and that they are not synonyms.
What actually happens
You agree a scope and sign authorisation. The tester maps the surface, then tries to exploit it, usually with accounts you provide. Critical issues are called in as they are confirmed. At the end you get a report, a debrief, and later a retest of the fixes.
The five-phase picture, if you like pictures: scope, recon, exploit, report, retest. Skip any one of those and you do not have a pentest. You have a scan, a rumour, or a very expensive conversation.
What you should get
An executive summary a non-specialist can read. A findings table. Per-finding evidence and reproduction. A severity scheme you recognise (we use CVSS 3.1). A retest. An attestation if you asked for one. If the pack is a CSV of CVEs, you bought a scan.
How to tell a rebadged scan
No mention of roles or accounts. No logic findings, ever, across three years of reports. Delivery in 48 hours on a large app. A junior on the call and a tool on the invoice. None of those is illegal. All of them are a waste of the budget you will have to spend again.
If you want the version we run: services, methodology, quote.